CVE-2008-3353: XSS
Published Jul 28, 2008
·Updated
Multiple cross-site scripting (XSS) vulnerabilities in Pure Software Lore before 1.7.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to the (1) article comments feature and the (2) search log feature.
Affected Software
32 affected components
Puresw Lore=1.5.9
Puresw Lore=1.6.1
Puresw Lore=1.1.1
Puresw Lore=1.5.3
Puresw Lore=1.1.0
Puresw Lore=1.5.5
Puresw Lore=1.0.8
Puresw Lore=1.5.6
Puresw Lore<=1.6.3
Puresw Lore=1.0.9
Puresw Lore=1.6.0
Puresw Lore=1.5.1
Puresw Lore=1.4.0
Puresw Lore=1.5.4
Puresw Lore=1.3.0
Puresw Lore=1.5.8
Puresw Lore=1.0.7
Puresw Lore=1.4.1
Puresw Lore=1.2.0
Puresw Lore=1.0.2
Puresw Lore=1.4.2
Puresw Lore=1.4.3
Puresw Lore=1.0.5
Puresw Lore=1.0.3
Puresw Lore=1.1.2
Puresw Lore=1.2.1
Puresw Lore=1.0.6
Puresw Lore=1.0.4
Puresw Lore=1.5.0
Puresw Lore=1.5.2
Puresw Lore=1.5.7
Puresw Lore=1.6.2
Event History
Jul 28, 2008
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-3353?
CVE-2008-3353 has been classified as a medium severity Cross-Site Scripting (XSS) vulnerability.
2
How do I fix CVE-2008-3353?
To fix CVE-2008-3353, upgrade to Pure Software Lore version 1.7.0 or later.
3
What are the affected versions for CVE-2008-3353?
CVE-2008-3353 affects Pure Software Lore versions prior to 1.7.0 including 1.0.2 through 1.6.3.
4
What features are vulnerable in CVE-2008-3353?
CVE-2008-3353 affects the article comments feature and the search log feature in Pure Software Lore.
5
Can CVE-2008-3353 be exploited remotely?
Yes, CVE-2008-3353 allows remote attackers to inject arbitrary web scripts or HTML.